Vulnerability Description
A vulnerability in ICMP Version 6 (ICMPv6) processing in Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a slow system memory leak, which over time could lead to a denial of service (DoS) condition. This vulnerability is due to improper error handling when an IPv6-configured interface receives a specific type of ICMPv6 packet. An attacker could exploit this vulnerability by sending a sustained rate of crafted ICMPv6 packets to a local IPv6 address on a targeted device. A successful exploit could allow the attacker to cause a system memory leak in the ICMPv6 process on the device. As a result, the ICMPv6 process could run out of system memory and stop processing traffic. The device could then drop all ICMPv6 packets, causing traffic instability on the device. Restoring device functionality would require a device reboot.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Nx-Os | 5.2\(1\)sv5\(1.3a\) |
| Cisco | Nexus 1000 Virtual Edge For Vmware Vsphere | - |
| Cisco | Nexus 1000V Switch For Microsoft Hyper-V | - |
| Cisco | Nexus 1000V Switch For Vmware Vsphere | - |
| Cisco | Mds 9148S | - |
| Cisco | Mds 9250I | - |
| Cisco | Mds 9706 | - |
| Cisco | Mds 9710 | - |
| Cisco | Nexus 3048 | - |
| Cisco | Nexus 31108Pv-V | - |
| Cisco | Nexus 31108Tc-V | - |
| Cisco | Nexus 31128Pq | - |
| Cisco | Nexus 3132C-Z | - |
| Cisco | Nexus 3132Q-V | - |
| Cisco | Nexus 3132Q-X | - |
| Cisco | Nexus 3132Q-Xl | - |
| Cisco | Nexus 3164Q | - |
| Cisco | Nexus 3172Pq | - |
| Cisco | Nexus 3172Pq-Xl | - |
| Cisco | Nexus 3232C | - |
Related Weaknesses (CWE)
References
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fVendor Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fVendor Advisory
FAQ
What is CVE-2021-1229?
CVE-2021-1229 is a vulnerability with a CVSS score of 5.8 (MEDIUM). A vulnerability in ICMP Version 6 (ICMPv6) processing in Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a slow system memory leak, which over time could lead to a denial...
How severe is CVE-2021-1229?
CVE-2021-1229 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-1229?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Nx-Os, Cisco Nexus 1000 Virtual Edge For Vmware Vsphere, Cisco Nexus 1000V Switch For Microsoft Hyper-V, Cisco Nexus 1000V Switch For Vmware Vsphere, Cisco Mds 9148S.